Skip to main content

Lab Setup & Prerequisites

Pre-Labโฑ 15 min๐Ÿ‘ค All Personas
Lab Setup & Prerequisites

Complete these steps before starting Lab 1. You will access your lab VM, log into both Zscaler tenants, configure the Zscaler Client Connector forwarding profile, and verify notifications are enabled. Allow 15 minutes.

Credentials in Your Email

All access details โ€” Skytap VM link, tenant usernames, and passwords โ€” were sent to you by the Zscaler Training Team before the session. Keep that email open throughout the lab.


Lab Environment Overviewโ€‹

Your lab environment consists of two components:

Lab environment โ€” Corp Client PC connected through Zscaler Zero Trust Exchange to the Internet

ComponentDescription
Corp Client PCA Windows VM hosted in Skytap. Used for all Kevin (end user) tasks in Labs 6, 7, and 8.
Admin PortalThe Zscaler console accessed from your own laptop. Used for all Alex and Priya tasks.
Zscaler CloudYour traffic and DLP enforcement plane. ZCC on the VM routes all traffic through Zscaler.

Part 1 โ€” Access Your Lab Environmentโ€‹

Step 1 โ€” Check Your Emailโ€‹

Look for an email from Zscaler Training Team with subject Data Security (EDU-220) - Instructor Led Training.

Zscaler Training Team welcome email with lab access details

The email contains:

  • Skytap URL โ€” unique link to your lab VM (no password required)
  • ZIdentity Landing Page โ€” for Lab Tenant access
  • Student Admin Username โ€” student@zs000XXX.labtenant.com
  • One Time Password โ€” you will be prompted to change this on first login
  • SDC Credentials โ€” for Enterprise Tenant access

Step 2 โ€” Access the Lab VMโ€‹

Click your Skytap URL from the email. The Windows VM launches automatically โ€” no username or password required.

Lab access details from email โ€” Skytap URL and ZIdentity credentials

Verify the VM is ready:

  • Zscaler Client Connector icon visible in the system tray
  • File Dataparity_Q2_2025_Workforce_Financial_Summary.docx is on the Desktop

Step 3 โ€” Log Into the Enterprise Tenant (Modules 1 & 3)โ€‹

From your laptop browser, navigate to https://sdc.zslogin.net/ and log in with your SDC Admin credentials from the email.

SDC Enterprise Tenant credentials

FieldValue
Login URLhttps://sdc.zslogin.net/
Admin Usernameca-XXXX-ADMIN@thezerotrustexchange.com
PasswordFrom your email

Step 4 โ€” Log Into the Lab Tenant (Module 2)โ€‹

From your laptop browser, navigate to your ZIdentity Landing Page from the email (format: zs000XXX.zslogin.net) and log in with your Student Admin credentials. You will be prompted to set a new password on first login.

๐Ÿ’ก Two Tenants โ€” Know the Difference
TenantUsed InAccessLogin URL
Enterprise Tenant (SDC)Modules 1 + 3Read-Onlysdc.zslogin.net
Lab TenantModule 2 onlyRead/WriteYour ZIdentity URL from email

The facilitator will indicate when to switch tenants at the start of each module.


Part 2 โ€” Configure Zscaler Client Connector (Lab Tenant)โ€‹

These steps configure the Client Connector forwarding profile and app policy on the lab VM. This is required for Labs 6, 7, and 8 to enforce DLP policies on endpoint traffic.

Lab Tenant Required

All steps in Part 2 are performed in the Lab Tenant using the ZIdentity Client Connector tile. Make sure you are logged into the Lab Tenant before proceeding.

Step 5 โ€” Log Into ZIdentity and Open Client Connectorโ€‹

On the Corp Client PC (VM), open Chrome and navigate to your ZIdentity Landing Page. Log in with your Student Admin credentials, then click the Zscaler Client Connector tile.

ZIdentity landing page โ€” select Zscaler Client Connector tile

Step 6 โ€” Navigate to Forwarding Profileโ€‹

Navigate to:

Administration โ†’ Forwarding Profile

Navigate to Forwarding Profile in ZCC Administration

Step 7 โ€” Add Forwarding Profileโ€‹

Click Add Forwarding Profile and configure:

  • Name: HandsOnLab_FW_Profile
  • Windows Driver Selection: Packet Filter Based

Add Forwarding Profile โ€” name and driver selection

Step 8 โ€” Configure ZIA Tunnel Settingsโ€‹

In the FORWARDING PROFILE ACTION FOR ZIA section:

  • On-Trusted Network: Tunnel
  • Tunnel version: Z-Tunnel 2.0

ZIA forwarding profile โ€” Tunnel and Z-Tunnel 2.0 selection

Step 9 โ€” Configure System Proxy Settingsโ€‹

Scroll down and expand Configure System Proxy Settings:

  • Configure System Proxy Settings: Enforce
  • Ensure all options are unchecked

Configure System Proxy Settings โ€” Enforce selected, all options unchecked

Step 10 โ€” Configure VPN and Off-Trusted Networkโ€‹

  • VPN Trusted Network: Check Same as "On-Trusted Network"
  • Off Trusted Network: Check Same as "On-Trusted Network"

VPN Trusted Network and Off-Trusted Network โ€” Same as On-Trusted Network

Step 11 โ€” Configure ZPA Forwarding Profileโ€‹

In the FORWARDING PROFILE ACTION FOR ZPA section:

  • On-Trusted Network: Tunnel
  • VPN-Trusted Network: Same as "On-Trusted Network"
  • Off-Trusted Network: Same as "On-Trusted Network"

Click Save.

ZPA forwarding profile action settings

Step 12 โ€” Navigate to App Profilesโ€‹

Navigate to:

App Profiles โ†’ Windows

Navigate to App Profiles โ€” Windows

Step 13 โ€” Add Windows App Policyโ€‹

Click Add Windows Policy and configure:

  • Name: HandsOnLab_App_Profile
  • Rule Order: 1
  • Status: Enable
  • Forwarding Profile: HandsOnLab_FW_Profile
  • Install Zscaler SSL Certificate: On
  • User Groups: Select All โ†’ Done

Add Windows App Policy configuration

Step 14 โ€” Enable Data Protection / Endpoint DLPโ€‹

In the same Windows App Policy:

  • Data Protection: Install Endpoint ZDP
  • Expand Notification and Logging:
    • Use Zscaler Notification Framework: Enable
    • Bring Notification to Focus: Enable

Click Add.

Add DLP Module โ€” Data Protection and notification settings

Step 15 โ€” Enable Client Connector Notificationsโ€‹

Navigate to:

Administration โ†’ Client Connector Notification โ†’ Notification Template
note

You can either edit the existing Legacy Notification Settings template (click the edit icon) or create a new template using the + Add Notification Template button. Either approach works โ€” just ensure the template is saved and active before proceeding.

Click the edit icon next to Legacy Notification Settings.

Navigate to Administration โ†’ Client Connector Notification โ†’ Notification Template tab and click edit on Legacy Notification Settings

Configure the following settings in the Edit Notification Template dialog:

SettingValue
Show ZCC Notification Popups by DefaultEnabled
Enable Service Status NotificationsEnabled
Enable ZIA NotificationsEnabled
Enable Persistent NotificationsEnabled
Enable Notifications for ZPA ReauthenticationEnabled
Custom Timer (In Seconds)5

Click Save.

Edit Notification Template โ€” all notification toggles enabled with 5-second custom timer

๐Ÿ’ก Facilitator Notes

Steps 5โ€“15 configure the forwarding profile and enable endpoint DLP notifications. This is required before Labs 6, 7, and 8 โ€” without these steps, the ZCC block notifications will not appear on screen when Kevin's actions are blocked. Allow 5โ€“7 minutes for all students to complete these steps.


Part 3 โ€” Navigate to Experience Center (Module 2)โ€‹

For all Module 2 configuration tasks (Labs 5, 6, and 7), Alex uses the Experience Center โ€” Zscaler's unified console โ€” rather than the standard admin portal.

After logging into the Lab Tenant, click Experience Center in the banner at the top of the ZIdentity page.

ZIdentity app launcher โ€” click Experience Center in the top banner

Callout โ€” Click Experience Center in the blue banner at the top

The Experience Center provides a unified view of all Zscaler products and is the primary console for configuring DLP policies, engines, and resources in Labs 5, 6, and 7.


Part 4 โ€” Setup VM and Login to Zscaler Client Connector (ZCC)โ€‹

Step 1 โ€” Login to the VMโ€‹

Locate the Skytap URL in your lab access email and click it. The Windows VM launches automatically โ€” no username or password required.

note

If you log off or need to log back in manually, use username: student / password: Admin-123!

Skytap link highlighted in the lab access email

Step 2 โ€” Open and Login to Zscaler Client Connectorโ€‹

Locate the ZCC icon in the system tray (bottom right of the taskbar) โ‘ , right-click it, and select Open Zscaler โ‘ก. The Zscaler Client Connector window opens โ‘ข.

Use your Lab Tenant credentials to log in โ€” the same username and password you set up in Part 3.

note

Use your updated password, not the one-time password from the email. ZIdentity prompted you to change it on first login โ€” use that new password here.

ZCC system tray icon, right-click menu, and login screen

Tip โ€” Copy/Paste from your local machine to the VM:

Use the VM Clipboard tool in the SkyTap toolbar at the top of the VM window โ‘ . Paste your credential into the clipboard field, then paste inside the VM using Ctrl+V. This works in both directions โ€” local to VM and VM to local โ‘ก.

SkyTap VM Clipboard tool for copy/paste between local machine and VM

Step 3 โ€” Verify All Modules Are Activeโ€‹

Once logged in, the ZCC dashboard opens. Confirm the following:

  • Authentication Status: Authenticated (green)
  • Service Status: ON
  • All modules (Private Access, Internet Security, Digital Experience, Data Protection) are visible and active

ZCC dashboard showing all modules active and authentication status Authenticated

Step 4 โ€” Verify Traffic Is Being Steered to Zscalerโ€‹

Open a browser inside the VM and navigate to https://ip.zscaler.com. The page should confirm your traffic is passing through the Zscaler Zero Trust Exchange and display your Zscaler proxy details.

ip.zscaler.com confirming traffic is tunneled through Zscaler Cloud

note

Notepad++ is pre-installed on the VM โ€” no installation needed. It is ready to use for Lab 7.


Quick Reference โ€” All Credentialsโ€‹

WhatURLUsernamePassword
Enterprise Tenant (Admin)https://sdc.zslogin.net/ca-XXXX-ADMIN@thezerotrustexchange.comFrom email
Lab TenantZIdentity URL from emailstudent@zs000XXX.labtenant.comOne Time Password from email
Browser DLP Extension (Lab 8)Tenant: dlpdemoSame as Enterprise Tenant AdminSame as Enterprise Tenant
Lab VMSkytap URL from emailstudentAdmin-123!
Zscaler Client Connector (VM)N/ASame as Lab Tenant Admin usernameSame as updated Lab Tenant password
Screenshots May Show Different Numbers

The ca-XXXX and zs000XXX numbers in screenshots throughout this lab guide were captured during preparation. Use the credentials from your email.

๐Ÿ’ก Facilitator Notes

Before moving to Lab 1, do a quick show-of-hands:

  • Can everyone access the Enterprise Tenant at sdc.zslogin.net? โœ‹
  • Can everyone access their Lab Tenant? โœ‹
  • Has everyone completed the forwarding profile setup? โœ‹
  • Is Zscaler Client Connector logged in and all modules active on the VM? โœ‹
  • Does ip.zscaler.com confirm traffic is tunneled through Zscaler? โœ‹

Resolve any blockers before proceeding โ€” all subsequent labs depend on these steps being complete.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Introduction
Browse all topics